That’s typically how you show that something is vulnerable before it becomes a real problem.
I mean, criticize the headline if you want, but this is pretty standard reporting for this kind of thing. Recent stories on vulnerabilities in networked car systems were handled using the same approach. (It finally got attention, too, even though security researchers had been pointing out the same issues for years.)
Until the Chinese government penalizes these Chinese companies for these insecure practices, they'll continue to be sold as is. China doesn't need to care about Chinese made products sold for export apparently.
Why single out the Chinese government? No government anywhere cares about defective software. "Engineering" is certainly not the correct term to apply to this industry.
Yeah. I subscribe to a mailing list from a data security company that sends me a summary of breaches, daily. I know it is in their interest to keep me worried. But they aren’t making these stories up.
To be fair, in many (maybe all?) of those cases, those companies faced consequences. I highly doubt this company is going to face any consequence for this data breach.
AT&T was fined $177 million for one data breach, which represents 12 hours of revenue, and $13 million for the other, which represents 54 minutes of revenue. "Consequences". Right.
I see an opportunity for an import hurdle masquerading as a security compliance mark on all Chinese imports.
I doubt it will be implemented as there are no western cheap gadget industries left to lobby for it, and the big players would prefer the fud of buy cheap be tracked.
> China doesn't need to care about Chinese made products sold for export apparently.
Wait until you hear about this American car companies that makes vehicles so unsafe, they intentionally lock themselves down tight in an accident so the emergency services can't get people out of them, and presumably just have to sit there and burn to death with their rescuers half a metre away.
This is perfectly legal under US law. There are no safety regulations.
Do US markets (Amazon) hold any responsibility for what shady companies and their insecure products they enable to sell here, I wonder? Does our government, for import?
> made by an equally obscure manufacturer, YiQingTeng Electronics, in Shenzhen, China.
Is this what is meant by "Shenzhen Speed"? Dump all safeguards and get any piece of crap out the door as soon as possible? This comment isn't directed specifically at Shenzhen, as other parts of the world do the same thing and call it "Move fast and break things."
Dropping engineering standards may increase short term profits, but it erodes people's trust in the world around them when everything "sort of works".
There's an argument that this low level continuous corrosion does more long-term damage than obvious safety flaws that are serious enough to prompt corrective action.
> There's an argument that this low level continuous corrosion does more long-term damage than obvious safety flaws that are serious enough to prompt corrective action.
Unfortunately I just don't see much care being given to the long term well being of society right now. Not by many governments, not by many corporations.. it feels like everyone is in a "get rich by any means, fuck you I got mine" attitude.
Might as well not have any kind of society or rule of law at that point at all then. Zero trust societies, that's definitely the way towards a better life for all of us
If not, I have anecdotal counter info: saw a lot of work of a small team doing hardware testing/evaluation for a hardware reseller. Often using Chinese sources. Typical "our brand is good, but has to be slightly cheaper than competition". Some manufacturers are really good. But a lot of them send hardware so bad that it will electrocute you instantly. Which is wild in that profession - the whole point of sending samples to client is for them to disassemble it to asses quality. This is literally the only scenario, so any lie is instantly discovered.
One company asked for immediate return of a prototype because a client ordered a batch, but they don't know how was it made. They had zero documentation and had to check what was inside.
First to market usually wins. After they've got their gizmo in every user's hands, who will buy a perfectly crafted replacement with E2EE and all the bells and whistles?
Even if social popularity has always been of high importance in children’s and teens lives (just pause 1 min and try to remember how you were when aged 10 or 12), making a business of out it is quite sad.
What a world we live on…
If you need smartwatch to know where your children are at 10 PM you failed as parent, especially considering these watch are for young kids, not some teenagers with phones.
You think you're choosing between 20 different products, but underneath they may all be the same device talking to the same insecure backend. At that point "just research before you buy" isn't really useful advice
Buyer Beware has always been a terrible way to live. It guarantees the shittiest products rise to the top because most people do not seriously beware for every purchase they make. As is always the case, regulation and enforcement is what's needed.
How are you even supposed to evaluate the security of a product before you buy it and have it in your hands? It's not like there's an ecosystem of outlets doing that kind of work for the hundreds of thousands of internet-connected devices out there.
And even when it's in your hands, who has the time and expertise to thoroughly review a product for security issues?
I found this true with security camera & dvr systems. If you're shopping on amazon, you're mostly looking at the same devices and software, sometimes with slightly different styling, versions, and capabilities.
Most of them use the same cloud software to connect to the cameras.
There's better solutions if you have a bigger budget, or the ability to roll your own DVR solution...but on the cheap end, you're just stuck with this terrible software, chinese cloud, and...at least for me...zero trust in privacy. (I keep mine offline)
If you want to buy a smartwatch for your kids, or you want to have your kids wear something you can track, but them an Apple Watch SE. It has cellular and GPS, you can call them, you can see where they are, but they can't do much with it besides call you (and people you approve) and text people on an approved list.
It's private, it's secure, and it works with the stuff you already have.
But note that when you set it up in guardian/child mode, Apple - not your service provider - blocks it from international roaming.
Nice little Easter egg for you to only discover when you travel to a different country with your kid, or for your kid to discover alone when they travel! A family size surprise of the worst kind!
It works if you get a local sim card. The hardware is there. Just not allowed to roam.
fhub | a day ago
fsckboy | a day ago
NewsaHackO | a day ago
seizethecheese | a day ago
Sabinus | a day ago
iamnothere | a day ago
I mean, criticize the headline if you want, but this is pretty standard reporting for this kind of thing. Recent stories on vulnerabilities in networked car systems were handled using the same approach. (It finally got attention, too, even though security researchers had been pointing out the same issues for years.)
gkanai | a day ago
applfanboysbgon | a day ago
[1] Yahoo loses all of their 3 billion account credentials https://www.sec.gov/Archives/edgar/data/732712/0000732712170...
[2] Equifax loses PII of 150 million Americans, including their SSNs https://www.ftc.gov/enforcement/refunds/equifax-data-breach-...
[3] AT&T loses SSNs of 73 million customers https://about.att.com/story/2024/addressing-data-set-release...
[4] AT&T loses phone call/texting metadata of 110 million customers https://www.sec.gov/Archives/edgar/data/732717/0000732717240...
[5] Change Healthcare loses medical records of 200 million Americans https://www.hhs.gov/hipaa/for-professionals/special-topics/c...
To someone not drinking your nationalist kool-aid, it looks rather preposterous to make this about the Chinese bogeyman.
bjelkeman-again | a day ago
pjmlp | a day ago
Cybersecurity laws are a good start, however thanks to lobbying it will still take decades.
Gigachad | 23 hours ago
xmprt | 23 hours ago
applfanboysbgon | 23 hours ago
rapidaneurism | 23 hours ago
I doubt it will be implemented as there are no western cheap gadget industries left to lobby for it, and the big players would prefer the fud of buy cheap be tracked.
BrtByte | 23 hours ago
sejje | 10 hours ago
We could sure go a long way if China would start.
ErroneousBosh | 23 hours ago
Wait until you hear about this American car companies that makes vehicles so unsafe, they intentionally lock themselves down tight in an accident so the emergency services can't get people out of them, and presumably just have to sit there and burn to death with their rescuers half a metre away.
This is perfectly legal under US law. There are no safety regulations.
glaslong | 22 hours ago
femto | a day ago
Is this what is meant by "Shenzhen Speed"? Dump all safeguards and get any piece of crap out the door as soon as possible? This comment isn't directed specifically at Shenzhen, as other parts of the world do the same thing and call it "Move fast and break things."
Dropping engineering standards may increase short term profits, but it erodes people's trust in the world around them when everything "sort of works".
There's an argument that this low level continuous corrosion does more long-term damage than obvious safety flaws that are serious enough to prompt corrective action.
bluefirebrand | a day ago
Unfortunately I just don't see much care being given to the long term well being of society right now. Not by many governments, not by many corporations.. it feels like everyone is in a "get rich by any means, fuck you I got mine" attitude.
It's really sad
ryandrake | 23 hours ago
PradeetPatel | 22 hours ago
Don't be the person that's naive, easily cheated, and left behind while others move ahead because you refuse to take the optimal course of action.
bluefirebrand | 14 hours ago
small_scombrus | 23 hours ago
Very few companies seem to get into trouble for knowingly releasing products that are either faulty, insecure, or actively dangerous
szszrk | 20 hours ago
If not, I have anecdotal counter info: saw a lot of work of a small team doing hardware testing/evaluation for a hardware reseller. Often using Chinese sources. Typical "our brand is good, but has to be slightly cheaper than competition". Some manufacturers are really good. But a lot of them send hardware so bad that it will electrocute you instantly. Which is wild in that profession - the whole point of sending samples to client is for them to disassemble it to asses quality. This is literally the only scenario, so any lie is instantly discovered.
One company asked for immediate return of a prototype because a client ordered a batch, but they don't know how was it made. They had zero documentation and had to check what was inside.
theshrike79 | 21 hours ago
Shove it out as fast as possible, patch it live.
thenthenthen | a day ago
thomasben | 23 hours ago
Animats | a day ago
Markoff | 20 hours ago
vladmk | a day ago
Markoff | a day ago
Hackers Stalked Me by Hijacking a Smartwatch for Kids = clickbait title, that never happened, hacker done it in cooperation with the smartwatch owner
b3lvedere | 23 hours ago
BrtByte | 23 hours ago
ryandrake | 23 hours ago
InsideOutSanta | 9 hours ago
And even when it's in your hands, who has the time and expertise to thoroughly review a product for security issues?
sejje | 10 hours ago
Most of them use the same cloud software to connect to the cameras.
There's better solutions if you have a bigger budget, or the ability to roll your own DVR solution...but on the cheap end, you're just stuck with this terrible software, chinese cloud, and...at least for me...zero trust in privacy. (I keep mine offline)
jonahhorowitz | 23 hours ago
It's private, it's secure, and it works with the stuff you already have.
[0] - https://www.apple.com/apple-watch-for-your-kids/
ozozozd | 23 hours ago
Nice little Easter egg for you to only discover when you travel to a different country with your kid, or for your kid to discover alone when they travel! A family size surprise of the worst kind!
It works if you get a local sim card. The hardware is there. Just not allowed to roam.
ShinyLeftPad | 23 hours ago